We performed a comparison between Fortinet FortiSIEM and Nagios Core based on real PeerSpot user reviews.
Find out in this report how the two Security Information and Event Management (SIEM) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The analytic rule is the most valuable feature."
"Sentinel's most important feature is the ability to centralize all the logs in one place. There's no need to search multiple systems for information."
"I've worked on most of the top SIEM solutions, and Sentinel has an edge in most areas. For example, it has built-in SOAR capabilities, allowing you to run playbooks automatically. Other vendors typically offer SOAR as a separate licensed solution or module, but you get it free with Sentinel. In-depth incident integration is available out of the box."
"We didn't have anything similar. So, it really provides value from the incidents and automation point of view. The overview of the security fabric is most valuable."
"The most valuable features in my experience are the UEBA, LDAP, the threat scheduler, and integration with third-party straight perform like the MISP."
"Native integration with Microsoft security products or other Microsoft software is also crucial. For example, we can integrate Sentinel with Office 365 with one click. Other integrations aren't as easy. Sometimes, we have to do it manually."
"The SOAR playbooks are Sentinel's most valuable feature. It gives you a unified toolset for detecting, investigating, and responding to incidents. That's what clearly differentiates Sentinels from its competitors. It's cloud-native, offering end-to-end coverage with more than 120 connectors. All types of data logs can be poured into the system so analysis can happen. That end-to-end visibility gives it the advantage."
"If you know how to do KQL (kusto query language) queries, which are how you query the log data inside Sentinel, the information is pretty rich. You can get down to a good level of detail regarding event information or notifications."
"The most valuable feature is the anomaly-reporting alarms."
"Fortinet FortiSIEM is easy to use."
"AccelOps can handle a lot of data and it's just so important to true monitoring. Also, I can create a lot of rules to detect anything I like."
"The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted."
"The most valuable features for us are the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation."
"The advanced agents used to collect logs have been most valuable. We have also made use of the advanced intelligence this solution offers."
"The most valuable feature of Fortinet FortiSIEM is the correlation of many events."
"The stability is very reliable. It offers very good performance."
"The most valuable feature of Nagios Core is the ability to check the availability of the server for network connectivity. Additionally, the interface is good."
"Alert calls occur anytime a service goes down or a matrix is difficult and that helps us to quickly restore service and transfer work."
"Our customers like that Nagios Core is an open source solution. It can be customized to our customers' specific needs."
"It has made the life of the network operations staff more proactive in managing the resources of the infrastructure. It prevents disasters long before they can take place."
"Other products are good but from the configuration point of view Nagios is really very lightweight. The price is really good in my opinion. Another important thing is that my Nagios engine still works with Dual core 8GB ram for the last 10 years."
"What I like about Nagios Core is that it helps me ensure everything is running smoothly by checking the status of hosts and services."
"Nagios monitors our servers, so we know if anything goes wrong and can solve the problem before it happens."
"The most valuable feature is the performance parameters of the system."
"At the network level, there is a limitation in integrating some of the switches or routers with Microsoft Sentinel. Currently, SPAN traffic monitoring is not available in Microsoft Sentinel. I have heard that it is available in Defender for Identity, which is a different product. It would be good if LAN traffic monitoring or SPAN traffic monitoring is available in Microsoft Sentinel. It would add a lot of value. It is available in some of the competitor products in the market."
"They should just add more and more out-of-the-box connectors. It is quite a new product, and it has a lot of connectors, and even more would be good."
"It would be good to have some connectors for third-party SIEM solutions. Many customers are struggling with the integration of Azure Sentinel with their on-premise SIEM. Microsoft is changing the log structure many times a year, which can corrupt a custom integration. It would be good to have some connectors developed by Microsoft or supply vendors, but they are not providing such functionality or tools."
"I can't think of anything other than just getting the name out there. I think a lot of customers don't fully understand the full capabilities of Azure Sentinel yet. It is kind of like when they're first starting to use Azure, it might not be something they first think about. So, they should just kind of get to the point where it is more widely used."
"The learning curve could be improved. I am still learning it. We were able to implement the basic features to get them up and running, but there are still so many things that I don't know about all its features. They have a lot of features that we have not been able to use or apply. If they could work on reducing the solution's learning curve, that would be good. While there is a training course held by Microsoft to learn more about this solution, there is a cost associated with it."
"I believe one of the challenges I encountered was the absence of live training sessions, even with the option to pay for them."
"The solution could be more user-friendly; some query languages are required to operate it."
"They can work on the EDR side of things... Every time we need to onboard these kinds of machines into the EDR, we need to do it with the help of Intune, to sync up the devices, and do the configuration. I'm looking for something on the EDR side that will reduce this kind of work."
"The product does not have Security Orchestration and Automation Response, I would recommend adding this feature."
"The nodes on our network did not comply with the SIEM solution. They use a different format parking log."
"Does not have load-sharing or high-availability, and these are important things to implement. I can do the same things in another way, but not naturally having these features makes it complicated."
"The log collection and configuration management are not great."
"The reporting feature is not very attractive for the upper management and I am not able to perform complex/nested queries."
"The support of the product changed recently, and I don't think it's for the better. They should work to improve the support they offer to clients."
"The interface needs some improvements because it's a bit cumbersome when you're trying to view items. It takes some time to get used to. Additionally, sometimes the scrolling does not work."
"The dashboard needs to improve."
"Nagios Core is limited in terms of distributed setups, and there is no central view for remote data centers."
"It would be nice if the company offered a sales or contract manager that was dedicated to our company so that we would have some sort of link to Nagios, and if we had issues or questions, we'd be able to contact them directly."
"It's not that easy to install the product itself. Also, the UI is a bit hard for regular users to navigate through."
"Making it a little easier to configure and set up from the start would help. There are multiple layers that you have to wade through to be able to set it up, to do it the right way, and to get it to do what you want it to do."
"It is a bit slow due to latency."
"The UI is a little outdated and graphics could be displayed in a better way."
"The dashboard and monitoring features could be improved."
"I would like to see a sensor that shows the traffic of a user and what they're doing on the network."
Fortinet FortiSIEM is ranked 8th in Security Information and Event Management (SIEM) with 63 reviews while Nagios Core is ranked 7th in Network Monitoring Software with 46 reviews. Fortinet FortiSIEM is rated 7.6, while Nagios Core is rated 8.0. The top reviewer of Fortinet FortiSIEM writes "It's cheaper than other solutions with the same features but lacks integration with many third-party vendors". On the other hand, the top reviewer of Nagios Core writes "An Open Source Fully Featured Data Centre Monitoring Tool". Fortinet FortiSIEM is most compared with IBM Security QRadar, Splunk Enterprise Security, LogRhythm SIEM, Wazuh and ThousandEyes, whereas Nagios Core is most compared with Zabbix, Nagios XI, Centreon, Icinga and OP5 Monitor. See our Fortinet FortiSIEM vs. Nagios Core report.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.